Cross-source coverage
T1008 / ATT&CK
Fallback Channels
9 rules across 5 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.
- Tactics
- Command and Control
- Platforms
- ESXi · Linux · macOS · Windows
- Telemetry
-
WinEventLog:SysmonNSM:Flowauditd:SYSCALLmacos:unifiedlogesxi:vmkernelesxi:vpxd
How MITRE says to detect it DET0499
Behavioral Detection of Fallback or Alternate C2 Channels
Windows Analytic 1376
Establishing network connections on uncommon ports or protocols following C2 disruption or blocking. Often executed by processes that typically exhibit no network activity.
WinEventLog:SysmonEventCode=3, 22NSM:Flowuncommon ports
Linux Analytic 1377
Creation of outbound connections on alternate ports or using covert transport (e.g., ICMP, DNS) from non-network-intensive processes, following known disruption or blocked traffic.
auditd:SYSCALLoutbound connectionsNSM:Flowalternate ports
macOS Analytic 1378
Outbound fallback traffic from low-profile or background launch agents using unusual protocols or destinations after primary channel inactivity.
macos:unifiedlogNoneNSM:FlowNone
ESXi Analytic 1379
Outbound traffic from host management services or guest-to-host interactions over unusual interfaces (e.g., backdoor API endpoints or external VPN tunnels).
esxi:vmkernelNoneesxi:vpxdNone
SigmaHQ/sigma
4 rules| Detection | Severity | Format |
|---|---|---|
| Outlook Macro Execution Without Warning Setting Enabled | High | Sigma |
| Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting | High | Sigma |
| Suspicious Outlook Macro Created | High | Sigma |
| New Outlook Macro Created | Medium | Sigma |
Azure/Azure-Sentinel
2 rules| Detection | Severity | Format |
|---|---|---|
| Excessive NXDOMAIN DNS Queries (ASIM DNS Schema) | Medium | KQL |
| Potential DGA detected (ASIM DNS Schema) | Medium | KQL |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| possible_bind_or_reverse_shell_via_netcat_auditbeat_for_linux | Undefined | YARA-L |
elastic/protections-artifacts
1 rule| Detection | Severity | Format |
|---|---|---|
| OsaScript Download Cradle Spawned | Undefined | Elastic TOML |
splunk/security_content
1 rule| Detection | Severity | Format |
|---|---|---|
| Windows Outlook Macro Security Modified | Undefined | SPL |